Chile's Law 21.719 comes into force on 1 December 2026. From that date the operational deadlines run: 30 calendar days to answer a rights request, extendable once by 30 more (article 11), and breach reporting to the Agency without undue delay (article 14 sexies). A bill now before the Senate would move that date to 2027, but the enforceable date is still December 2026.
The essentials in 30 seconds
- Publication: December 13, 2024.
- Entry into force and oversight: December 1, 2026.
- Adjustment period: 24 months (that is the time you have to implement).
- ARSOP rights: response within the legal time limit (30 calendar days, extendable once by 30 more).
- Breaches: notification to the Agency without undue delay, by the most expedient means.
"When does it take effect?" is the question that comes up most often — but it is not the only date that matters. Once the law is mandatory, the clock starts running every time a customer exercises a right or a breach occurs. This is the table with every deadline in one place. If you want the full picture, start with the definitive guide to Law 21.719. If you want the full picture, start with our guide to the data protection law in Chile.
All deadlines and key dates
| Milestone or duty | Exact deadline | Basis |
|---|---|---|
| Publication of the law in the Official Gazette | 13 December 2024 | Law 21.719 |
| Entry into force and start of enforcement | 1 December 2026, first day of the twenty-fourth month after publication | First transitory article |
| Issuance of the law's regulations | Within six months of publication | Second transitory article |
| First appointment of the Agency's Board | Six months before entry into force | Fourth transitory article |
| Acknowledgement and reply to a rights request | 30 calendar days from receipt, extendable once by up to 30 more calendar days | Article 11 |
| Reply to a temporary blocking request | 2 business days from receipt | Article 11 |
| Data subject's claim before the Agency after a refusal | 30 business days | Articles 11 and 41 |
| Reporting a breach to the Agency | Without undue delay, by the most expedient means available | Article 14 sexies |
| Communicating the breach to data subjects | Required only where it affects sensitive data, data of children under fourteen, or economic, financial, banking or commercial data | Article 14 sexies |
| Adopting corrective measures after a sanction | 60 days; otherwise a 50% surcharge is added to the fine | Article 35 |
| Transitory window for smaller enterprises | First twelve months in force: the Agency may issue a written warning | Sixth transitory article |
| Limitation period to pursue infringements | 4 years from the occurrence of the act | Article 40 |
| Limitation period for imposed sanctions | 3 years from the decision becoming final | Article 40 |
| Entries in the sanctions register | Kept for the period the law sets, with free public access | Article 39 |
What happens on December 1, 2026?
It is the date on which the Personal Data Protection Agency can begin to audit and impose sanctions. The law was published in December 2024 and granted a 24-month adjustment period precisely so organizations would arrive prepared. That window is running out: in practice, adjustment projects take between 1 and 6 months depending on size, so the time to start is before the deadline, not on it.
Since 1 September 2026 the Senate has been considering a bill that would move that date to 1 December 2027 and expand the Agency's Board from three to five members. It is a bill, not a law: until it is published in the Official Gazette, the enforceable date is still 1 December 2026. Planning around an extension that does not yet exist is the risk, not the precaution.
Deadlines to respond to rights (ARSOP)
Once the law is in force, any person may exercise their rights of Access, Rectification, Erasure, Objection and Portability. The organization must respond within the legal time limit of 30 calendar days. The problem is usually not the deadline itself, but not having a channel or a procedure ready when the first request arrives. We walk through the full flow —identity verification, exceptions and templates— in how to respond to ARSOP rights requests.
Deadlines in the event of a security breach
In the face of an incident affecting personal data, notification to the Agency must be made without undue delay and by the most expedient means possible. The law does not set a fixed number of hours; the 72-hour figure is an international best-practice benchmark. In addition, you must communicate to the affected individuals when the breach involves sensitive data, data of children and adolescents, or economic and financial data. That is why it pays to have the procedure rehearsed before you need it.
Why it does not pay to wait
Several compliance actions —contracts with processors, consent management, security measures— depend on third parties and on implementation time. Reaching December 1, 2026 with a documented plan under way, even if not everything is closed, demonstrates proactive accountability and serves as a mitigating factor. If you want to organize the work by area, use the compliance checklist.
Will you make it in time for December 1, 2026?
A 30-minute assessment tells you how much is left and in what order to move forward. No obligation.
Book an assessmentFrequently asked questions
When does Law 21.719 take effect?
It was published on December 13, 2024, and becomes fully mandatory on December 1, 2026, after a 24-month adjustment period. From that date the Personal Data Protection Agency may audit and impose sanctions.
How long is the adjustment period under Law 21.719?
24 months, counted from publication (December 13, 2024) until oversight begins (December 1, 2026). It is the time to implement compliance.
What is the deadline to respond to ARSOP rights?
Within the legal time limit of 30 calendar days, extendable once by up to 30 more. That is why it is essential to have a defined channel and procedure in place before the requests arrive.
What is the deadline to notify a security breach?
To the Agency, without undue delay and by the most expedient means possible. To affected individuals, when the breach involves sensitive data, data of children and adolescents, or economic and financial data.
Why does Law 21.719 come into force precisely on 1 December 2026?
Because the first transitory article of Law 21.719 sets entry into force on the first day of the twenty-fourth month after its publication in the Official Gazette. Published on 13 December 2024, that calculation lands on 1 December 2026. It is not a discretionary date and the Agency cannot postpone it.
Is the deadline to answer rights requests in business or calendar days?
Calendar days. Article 11 of Law 21.719 requires the controller to acknowledge receipt and rule no later than thirty calendar days from the request being filed, extendable once by up to thirty further calendar days. Counting them as business days is the most common error in Chile.
Is there a 72-hour breach notification deadline in Chile?
No. The 72 hours belong to article 33 of the European GDPR. Article 14 sexies of Law 21.719 requires reporting to the Agency "by the most expedient means available and without undue delay", without fixing a number of hours. In practice that standard is stricter, not looser.
What is the deadline to answer a temporary blocking request?
Two business days from receipt, under article 11 of Law 21.719. Until it rules, the controller may not process the data covered by the request. Blocking does not affect storage, and if the request is refused the reply must be reasoned and communicated electronically to the Agency.
How long does a data subject have to claim before the Agency?
Thirty business days. Article 11 of Law 21.719 requires the controller to state that deadline to the data subject when refusing a request in whole or in part, and the procedure follows article 41. The same period runs where the controller simply fails to reply within the thirty calendar days.
When do infringements and sanctions become time-barred?
Article 40 of Law 21.719 sets four years for actions pursuing liability, counted from the occurrence of the act, and three years for sanctions already imposed, counted from the decision becoming final. For continuing infringements the period runs from the day the infringement ceased.
Official sources
- Law 21.719 on the protection and processing of personal data, creating the Personal Data Protection Agency — official text, Library of the National Congress of Chile
- Article 11 (response deadlines), article 14 sexies (breach reporting) and article 40 (limitation periods) — consolidated text in force from 1 December 2026
This article is for information purposes only and does not constitute legal advice for a specific case.